IT and Cyber Control & Compliance Officer (Expert) - BNP Paribas Fortis
Description
Join the Governance, Risk and Compliance team at BNP Paribas Fortis as an expert IT and Cyber Control & Compliance Officer. The team supports IT and Business Units in defining, implementing and maintaining an IT and Information Security Management System. Its purpose is to enable sound, formal risk decisions by management. The Norms & Control team develops group-derived and locally designed controls to mitigate ICT risk and demonstrate internal and regulatory compliance.
You will analyze, identify, design and deploy ICT controls, with a particular focus on regulations and standards. The assignment includes coordinating control execution, checking the completeness and adequacy of evidence, and testing effectiveness. You will advise on remediation and track corrective actions. You will also report results to management, stakeholders and Internal Audit while helping update processes and procedures.
The role requires substantial experience in information security, IT process controls and regulatory standards. You will work with multiple teams and external resources, explain control needs to business stakeholders and prepare clear material for senior management. Fluent French and English are mandatory, while Dutch and several professional certifications are preferred. The Brussels-based assignment runs from 19 October 2026 to 30 April 2027 with a 50/50 on-site and homeworking arrangement.
Top Reasons to Apply
Cyber risk impact
Regulatory compliance expertise
Senior stakeholder exposure
Cross-functional team collaboration
Hybrid work flexibility
Detailed Responsibilities and Skills
Additional Responsibilities
- Monitor ICT control execution
- Assure control evidence completeness
- Verify control evidence adequacy
- Test ICT control effectiveness
- Advise on control remediation
- Report ICT control results to management
- Report ICT control results to stakeholders
- Report ICT control results to Internal Audit
- Track control remediation actions
- Create ICT control processes
- Update ICT control procedures
General skills and business experience — mandatory
- French fluent speaking and writing
- English fluent speaking and writing
- Master's degree in IT or science, engineering degree with strong ICT controls background, proven equivalent experience/skills, or ICT Audit/ICT controls certification
- At least five years of Information Security and IT Process Controls management experience
- Understanding end-to-end ICT process flows and control needs
- Explaining ICT needs and controls to business stakeholders
- Drafting reports, memos and presentations for senior management
- Proactive attitude
- Delivering within deadlines
- Prioritization skills
- Strong analytical skills
- Attention to detail
- Ability to challenge
- Producing structured and concise documents
- Excellent English writing skills
- Working in dynamic multicultural environments
- Team-player collaboration
Technical skills and standards — mandatory
- Five years of IT and Security controls experience
- Knowledge of IT/Security procedures and standards
- Experience defining metrics and dashboards
- Experience designing and deploying ICT process controls
- Coordination and collaboration with different teams and external resources
- Experience with regulatory requirements, ISO/IEC standards including ISO 27001, and laws/regulations including CHAPS, CIS and ANSSI
Tools and methodologies
- Metrics definition and dashboarding (mandatory)
- ICT process control design and deployment (mandatory)
- ISO/IEC 27001 and applicable standards/regulations (mandatory)
- Agile methodology (preferred)
- No specific software tool named
Preferred skills, qualifications and experience
- Good Dutch speaking and writing
- ISO 27000-series certification
- CISA certification
- CISSP certification
- Project management and coordination skills
- Knowledge of Agile methodology
- Banking environment experience